3 дня назад
DevSecOps Adoption Practitioner (DevSecOps)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
DevSecOps Adoption Practitioner (DevSecOps): Embedding security practices within engineering squads by configuring security tooling, reviewing code, and building compliance evidence pipelines with an accent on SAST/DAST, SBOM automation, secrets management, and IAM. Focus on triaging vulnerabilities with developers, enforcing CI/CD security gates, and enabling teams on secure coding and OWASP Top 10 practices.
Location: Cluj-Napoca, Romania; office attendance required three days per week
Company
delivers software engineering services through distributed squads embedded in client product delivery teams.
What you will do
- Review pull requests for vulnerabilities and explain security issues to developers in actionable terms.
- Configure and maintain SAST tools including SonarQube, Checkmarx, and Semgrep within CI/CD pipelines.
- Implement DAST scanning for APIs and services and triage findings with developers.
- Generate and maintain SBOMs, automate release updates, and manage dependency scanning and vulnerability remediation.
- Implement secrets management, credential rotation, least-privilege IAM, and security group and network policy reviews in AWS.
- Produce security evidence for governance and InfoSec reviews and conduct enablement sessions on OWASP Top 10 and secure coding.
Requirements
- 5+ years of security engineering or DevSecOps experience with hands-on security tooling.
- Experience with SAST and DAST tools, including SonarQube, Checkmarx, Semgrep, OWASP ZAP, and Burp Suite.
- Experience with SBOM standards and tools including CycloneDX, SPDX, Syft, and Grype.
- Experience with dependency scanning, CVE triage, secrets management, and vulnerability remediation.
- Experience with AWS IAM, least-privilege practices, and CI/CD security gates using GitHub Actions or Jenkins.
- Proficient English at B2+ level for technical communication.
Nice to have
- CSSLP, CEH, or AWS Security Specialty certification.
- Experience with financial services regulatory compliance, including FCA or ISO 27001.
- Background in web application or API penetration testing.
Culture & Benefits
- Work on a long-term modernization program for a global financial markets infrastructure provider.
- Vacation according to the laws of the country of employment.
- Health insurance support for employees and their loved ones.
- 10 days of sick pay without a doctor's note, followed by provisions under local law.
- Time off for state holidays according to the official calendar.
- Certification cost coverage, access to courses and learning platforms, and company social events.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
7 часов назад
Staff Security Engineer (SecOps & Threat)
15 часов назад
Senior IT Security Engineer (AI/ML Security)
4 дня назад
Technical Support Specialist - Level 2 - Night Shift (Cybersecurity)
5 часов назад
Cybersecurity Engineer
4 дня назад
Corporate Security Manager (Defense Drones)
22 часа назад